Crate sha2

RustCrypto: SHA-2

crate Docs Apache2/MIT licensed Rust Version Project Chat Build Status

Pure Rust implementation of the SHA-2 cryptographic hash algorithms.

There are 6 standard algorithms specified in the SHA-2 standard: Sha224, Sha256, Sha512_224, Sha512_256, Sha384, and Sha512.

Algorithmically, there are only 2 core algorithms: SHA-256 and SHA-512. All other algorithms are just applications of these with different initial hash values, and truncated to different digest bit lengths. The first two algorithms in the list are based on SHA-256, while the last four are based on SHA-512.

Examples

One-shot API

use sha2::{Sha256, Digest};
use hex_literal::hex;

let hash = Sha256::digest(b"hello world");
assert_eq!(hash, hex!("b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9"));

Incremental API

use sha2::{Sha256, Sha512, Digest};
use hex_literal::hex;

let mut hasher = Sha256::new();
hasher.update(b"hello ");
hasher.update(b"world");
let hash256 = hasher.finalize();

assert_eq!(hash256, hex!("b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9"));

let mut hasher = Sha512::new();
hasher.update(b"hello world");
let hash512 = hasher.finalize();

assert_eq!(hash512, hex!(
    "309ecc489c12d6eb4cc40f50c902f2b4d0ed77ee511a7c7a9bcd3ca86d4cd86f"
    "989dd35bc5ff499670da34255b45b0cfd830e81f605dcf7dc5542e93ae9cd76f"
));

See the digest crate docs for additional examples.

Backends

This crate supports a number of different backends.

SHA-256 and SHA-512 backends:

SHA-256 only backends:

SHA-512 only backends:

By default the following backends are used:

You can force backend selection using the following configuration flags:

They can be enabled using either the RUSTFLAGS environment variable (e.g. RUSTFLAGS='--cfg sha2_backend="soft"'), or by modifying your .cargo/config.toml file.

Note that sha2_backend has higher priority than sha2_256_backend and sha2_512_backend. In other words, using --cfg sha2_backend="soft" --cfg sha2_256_backend="x86_sha" will result in selection of the software backend for SHA-256.

By default soft and riscv-zknh backends unroll round loops, which results in a better performance at the cost of a bigger resulting binary. You can disable unrolling in the backends by using sha2_backend_soft = "compact" and sha2_backend_riscv_zknh = "compact" configuration flags respectively.

License

The crate is licensed under either of:

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

Modules

Structs

Traits